Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 4/30/2015
Suchlauf-Zeit: 12:53:19 PM
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.04.30.03
Rootkit Datenbank: v2015.04.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Sylwia
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 374206
Verstrichene Zeit: 31 Min, 27 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.MultiPlug, C:\ProgramData\{9c3a366c-4089-0894-9c3a-a366c408d9b1}\Alpha Dog (2006) 1080p BrRip 5.1 x264 aac [TuGAZx].exe, 2020, Löschen bei Neustart, [9a218fe32664d363b34560ee847eaa56]
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 2
PUP.Optional.MultiPlug.Uns, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{37476589-E48E-439E-A706-56189E2ED4C4}_is1, In Quarantäne, [17a4e48e6e1c43f3792793aeb64d46ba],
PUP.Optional.UpgradeLeader.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\bff42538, In Quarantäne, [6358afc34842c96dacb265f3e61fb848],
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 1
PUP.Optional.NoMoreAds.A, C:\ProgramData\NoMore Ads, In Quarantäne, [4e6d363c13771f17f60c14a156adf907],
Dateien: 6
PUP.Optional.MultiPlug, C:\ProgramData\{9c3a366c-4089-0894-9c3a-a366c408d9b1}\Alpha Dog (2006) 1080p BrRip 5.1 x264 aac [TuGAZx].exe, Löschen bei Neustart, [9a218fe32664d363b34560ee847eaa56],
PUP.Optional.MultiPlug.Uns, C:\ProgramData\NoMore Ads\NoMore Ads.exe, In Quarantäne, [17a4e48e6e1c43f3792793aeb64d46ba],
PUP.Optional.Multiplug, C:\Program Files\UpgradeLeader\UpgradeLeader.dll, In Quarantäne, [ffbc6a08deac112556b7f83ad62c4db3],
PUP.Optional.Multiplug.A, C:\Program Files\Mozilla Firefox\dbghelp.dll, In Quarantäne, [8e2d9bd79cee5dd932be7ece7e840000],
PUP.Optional.Multiplug.A, C:\Program Files\SalePlUsu\SalePlUsu.exe, In Quarantäne, [209b83ef91f9ea4c76430d25a161e41c],
PUP.Optional.MultiPlug, C:\Users\Sylwia\Downloads\Alpha Dog (2006) 1080p BrRip 5.1 x264 aac [TuGAZx].exe, In Quarantäne, [eecd551df2988fa723d53a14fe049d63],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
# AdwCleaner v4.202 - Logfile created 30/04/2015 at 13:56:55
# Updated 23/04/2015 by Xplode
# Database : 2015-04-27.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x86)
# Username : Sylwia - SYLWIA-PC
# Running from : C:\Users\Sylwia\Desktop\AdwCleaner_4.202.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\8c493d5a000041c5
Folder Deleted : C:\ProgramData\{9c3a366c-4089-0894-9c3a-a366c408d9b1}
Folder Deleted : C:\Program Files\SalePlUsu
Folder Deleted : C:\Users\Sylwia\AppData\Roaming\download Manager
Folder Deleted : C:\ProgramData\hkcfefjpmjbkidadhiommblmfcdmlfhe
File Deleted : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
File Deleted : C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\mxcdabcp.default\user.js
File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{bff42538}
Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Data Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17728
-\\ Mozilla Firefox v37.0.2 (x86 pl)
-\\ Google Chrome v42.0.2311.90
[C:\Users\Sylwia\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Sylwia\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
-\\ Opera v0.0.0.0
*************************
AdwCleaner[R0].txt - [9569 bytes] - [08/02/2015 18:13:42]
AdwCleaner[R1].txt - [2145 bytes] - [30/04/2015 13:35:17]
AdwCleaner[S0].txt - [12067 bytes] - [08/02/2015 18:21:06]
AdwCleaner[S1].txt - [2032 bytes] - [30/04/2015 13:56:55]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2091 bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.7 (04.30.2015:1)
OS: Windows 7 Professional x86
Ran by Sylwia on Thu 04/30/2015 at 14:05:20.77
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update Dynamo Combo
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util Dynamo Combo
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Sylwia\AppData\Roaming\mozilla\firefox\profiles\mxcdabcp.default\prefs.js
user_pref(extensions.4zzO4n7Zxx1sEbKr.scode, try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\rjk5pda6pjkEpjwGqdU7rHaFrjr\)>-1||u
user_pref(extensions.8osxbGtPMTwK8F21.scode, try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\rjk5pda6pjkEpjwGqdU7rHaFrjr\)>-1||u
user_pref(extensions.XG1JbXzPw5rvOiea.scode, (function(){try{if(window.location.href.indexOf(\rjk5pda6pjkEpjwGqdU7rHaFrjr\)>-1){return;}}catch(e){}try{var d=[[\trianglec
user_pref(extensions.fQyOPyDISYSuXG1r.scode, (function(){try{if(window.location.href.indexOf(\rjk5pda6pjkEpjwGqdU7rHaFrjr\)>-1){return;}}catch(e){}try{var d=[[\trianglec
user_pref(extensions.wEJW0Bu1XHg58h5c.scode, try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\rjk5pda6pjkEpjwGqdU7rHaFrjr\)>-1||u
user_pref(extensions.z5kxkbAzKf1puZCT.scode, (function(){try{if(window.location.href.indexOf(\rjk5pda6pjkEpjwGqdU7rHaFrjr\)>-1){return;}}catch(e){}try{var d=[[\trianglec
user_pref(extensions.zZalUZfnta815LZZ.scode, try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\rjk5pda6pjkEpjwGqdU7rHaFrjr\)>-1||u
Emptied folder: C:\Users\Sylwia\AppData\Roaming\mozilla\firefox\profiles\mxcdabcp.default\minidumps [13 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 04/30/2015 at 14:08:52.30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-04-2015 01
Ran by Sylwia (administrator) on SYLWIA-PC on 30-04-2015 14:26:06
Running from C:\Users\Sylwia\Desktop
Loaded Profiles: Sylwia (Available profiles: Sylwia)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\w32x86\3\NetFaxServer.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [DataCardMonitor] => C:\Program Files\blueconnect\DataCardMonitor.exe [259424 2011-08-31] (Huawei Technologies Co., Ltd.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [978520 2015-01-30] (Microsoft Corporation)
HKU\S-1-5-21-4051756106-1239465834-1114186828-1001\...\Run: [HW_OPENEYE_OUC_blueconnect] => C:\Program Files\blueconnect\UpdateDog\ouc.exe [116064 2011-03-26] (Huawei Technologies Co., Ltd.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-12-06] (Microsoft Corporation)
Startup: C:\Users\Sylwia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Alpha Dog (2006) 1080p BrRip 5.1 x264 aac [TuGAZx].lnk [2015-04-12]
ShortcutTarget: Alpha Dog (2006) 1080p BrRip 5.1 x264 aac [TuGAZx].lnk -> C:\ProgramData\{9c3a366c-4089-0894-9c3a-a366c408d9b1}\Alpha Dog (2006) 1080p BrRip 5.1 x264 aac [TuGAZx].exe (No File)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sylwia\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll [2012-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sylwia\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll [2012-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sylwia\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll [2012-11-06] (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-4051756106-1239465834-1114186828-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4051756106-1239465834-1114186828-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKU\S-1-5-21-4051756106-1239465834-1114186828-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKU\S-1-5-21-4051756106-1239465834-1114186828-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_31-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_31-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Winsock: Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 217.172.224.160 89.231.1.206
FireFox:
========
FF ProfilePath: C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\mxcdabcp.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2013-10-01] ()
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-10] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_31\bin\new_plugin\npjp2.dll No File
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-10] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-10] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: NoMore Ads - C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\mxcdabcp.default\Extensions\czlza_aesrs_r@bxufzmnphvdsevzsu.edu [2015-04-29]
FF Extension: British English Dictionary (Updated) - C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\mxcdabcp.default\Extensions\en-gb@flyingtophat.co.uk [2015-01-21]
FF Extension: Adblock Plus - C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\mxcdabcp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-22]
FF HKLM\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_Z\Bin\addon
FF Extension: Bytemobile Optimization Client - C:\Program Files\T-Mobile\InternetManager_Z\Bin\addon [2012-10-01]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Sylwia\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Sylwia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-10]
CHR Extension: (Google Search) - C:\Users\Sylwia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-10]
CHR Extension: (Bookmark Manager) - C:\Users\Sylwia\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-17]
CHR Extension: (Google Wallet) - C:\Users\Sylwia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-10]
CHR Extension: (Gmail) - C:\Users\Sylwia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-10]
Opera:
=======
StartMenuInternet: (HKLM) Opera - C:\Program Files\Opera\Opera.exe hxxp://isearch.omiga-plus.com/?type=sc&ts=1421626292&from=cor&uid=HitachiXHTS545032B9A300_090404PB0C00QPGHYWUAX
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [271712 2011-03-14] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [227232 2010-01-15] (McAfee, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe [165888 2010-03-08] (Samsung Electronics Co., Ltd.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [13184 2009-12-15] (Bytemobile, Inc.) [File not signed]
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2009-07-13] (Samsung Electronics Co., Ltd.) [File not signed]
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [90368 2011-02-25] (Huawei Technologies Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
S3 nokia_usb_modem_cdc_acm; C:\Windows\System32\DRIVERS\nokia_usb_modem_cdc_acm.sys [67968 2011-06-22] (Nokia)
S3 nokia_usb_modem_cdc_ecm; C:\Windows\System32\DRIVERS\nokia_usb_modem_cdc_ecm.sys [52224 2011-06-22] (Nokia)
S3 nokia_usb_modem_ecm_enum; C:\Windows\System32\DRIVERS\nokia_usb_modem_ecm_enum.sys [47488 2011-06-22] (Nokia)
S3 nokia_usb_modem_ecm_enum_filter; C:\Windows\System32\DRIVERS\nokia_usb_modem_ecm_enum_filter.sys [47488 2011-06-22] (Nokia)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-12] (Samsung Electronics) [File not signed]
R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [24192 2009-12-15] (Bytemobile, Inc.) [File not signed]
S3 zte_cdc_acm; C:\Windows\System32\DRIVERS\zte_cdc_acm.sys [67968 2011-08-10] (ZTE)
S3 zte_cpo; C:\Windows\System32\DRIVERS\zte_cpo.sys [9984 2011-08-10] (ZTE)
S3 catchme; \??\C:\Users\Sylwia\AppData\Local\Temp\catchme.sys [X]
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 14:25 - 2015-04-30 14:25 - 00002525 _____ () C:\Users\Sylwia\Desktop\mbam.txt
2015-04-30 14:08 - 2015-04-30 14:08 - 00002333 _____ () C:\Users\Sylwia\Desktop\JRT.txt
2015-04-30 14:05 - 2015-04-30 14:05 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-SYLWIA-PC-Windows-7-Professional-(32-bit).dat
2015-04-30 14:05 - 2015-04-30 14:05 - 00000000 ____D () C:\RegBackup
2015-04-30 14:03 - 2015-04-30 14:04 - 02716306 _____ (Thisisu) C:\Users\Sylwia\Desktop\JRT.exe
2015-04-30 13:34 - 2015-04-30 13:34 - 02224640 _____ () C:\Users\Sylwia\Desktop\AdwCleaner_4.202.exe
2015-04-29 19:19 - 2015-04-29 19:19 - 00028948 _____ () C:\ComboFix.txt
2015-04-29 17:09 - 2015-04-30 13:27 - 00000000 ____D () C:\Program Files\UpgradeLeader
2015-04-29 16:35 - 2015-04-29 16:35 - 00001226 _____ () C:\Users\Sylwia\Desktop\Revo Uninstaller.lnk
2015-04-29 16:21 - 2015-04-29 16:21 - 00000079 _____ () C:\Program Files\prefs.js
2015-04-29 00:27 - 2015-04-29 00:27 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Sylwia\Desktop\revosetup95.exe
2015-04-28 14:52 - 2015-04-28 14:52 - 00104960 _____ (GMER) C:\pwdiqpob.sys
2015-04-28 14:49 - 2015-04-28 14:49 - 00380416 _____ () C:\Users\Sylwia\Desktop\Gmer-19357.exe
2015-04-28 14:45 - 2015-04-28 14:50 - 00043173 _____ () C:\Users\Sylwia\Desktop\Addition.txt
2015-04-28 14:42 - 2015-04-30 14:26 - 00012020 _____ () C:\Users\Sylwia\Desktop\FRST.txt
2015-04-28 14:41 - 2015-04-28 14:41 - 01140736 _____ (Farbar) C:\Users\Sylwia\Desktop\FRST.exe
2015-04-28 14:36 - 2015-04-28 14:37 - 00000474 _____ () C:\Users\Sylwia\Desktop\defogger_disable.log
2015-04-28 14:35 - 2015-04-28 14:35 - 00050477 _____ () C:\Users\Sylwia\Desktop\Defogger.exe
2015-04-21 19:00 - 2015-04-30 13:27 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-20 18:24 - 2015-04-20 18:24 - 00000000 ____D () C:\Program Files\The Latest Versions of Google
2015-04-17 09:59 - 2015-04-28 12:41 - 00000020 _____ () C:\Users\Sylwia\AppData\Roaming\appdataFr3.bin
2015-04-15 22:59 - 2015-04-15 23:23 - 00000000 ____D () C:\Users\Sylwia\Downloads\A-Serious-Man{2009.DVDrip}vice
2015-04-15 18:45 - 2015-04-15 18:45 - 00002685 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-04-15 18:45 - 2015-04-15 18:45 - 00000000 ___RD () C:\Program Files\Skype
2015-04-15 18:45 - 2015-04-15 18:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-04-15 18:45 - 2015-04-15 18:45 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-04-15 11:54 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 11:54 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 11:54 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 11:54 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 11:54 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 11:54 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-15 11:54 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 11:54 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 11:54 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 11:54 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 11:54 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 11:54 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 11:54 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 11:54 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 11:54 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 11:54 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 11:54 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 11:54 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 11:54 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 11:54 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 11:54 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 11:54 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 11:54 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 11:54 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 11:54 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 11:54 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 11:54 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 11:53 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 11:53 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 11:53 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 11:53 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 11:53 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 11:53 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 11:53 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 11:53 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 11:53 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 11:53 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 11:53 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 11:53 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 11:53 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 11:53 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 11:53 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 11:53 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 11:53 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 11:53 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 11:53 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 11:53 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 11:53 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 11:53 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 11:53 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 11:53 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 11:53 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 11:53 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 11:53 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 11:53 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 11:53 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 11:53 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 11:53 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 11:52 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 11:52 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 11:52 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 11:52 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 11:52 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 11:52 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 11:52 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 11:52 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 11:52 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 11:52 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 11:52 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 11:52 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 11:51 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 11:51 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-11 12:20 - 2015-04-11 12:20 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2015-04-10 23:30 - 2015-04-10 23:30 - 00008770 _____ () C:\Users\Sylwia\Downloads\[kickass.to]big.hero.6.2014.720p.brrip.x264.yify.torrent
2015-04-10 23:30 - 2015-04-10 23:30 - 00008770 _____ () C:\Users\Sylwia\Downloads\[kickass.to]big.hero.6.2014.720p.brrip.x264.yify (1).torrent
2015-04-09 22:08 - 2015-04-09 22:08 - 00019625 _____ () C:\Users\Sylwia\Downloads\[kickass.to]about.time.2013.1080p.brrip.x264.yify.torrent
2015-04-09 17:08 - 2015-04-09 17:08 - 00017530 _____ () C:\Users\Sylwia\Downloads\[kickass.to]alpha.dog.2006.1080p.brrip.5.1.x264.aac.tugazx.torrent
2015-04-09 00:13 - 2015-04-09 00:13 - 00000000 ___SD () C:\Windows\system32\GWX
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 14:26 - 2015-02-06 20:00 - 00000000 ____D () C:\FRST
2015-04-30 14:12 - 2015-02-08 16:34 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-30 14:12 - 2009-07-14 06:34 - 00014848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-30 14:12 - 2009-07-14 06:34 - 00014848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-30 13:58 - 2010-08-19 14:18 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-30 13:58 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-30 13:58 - 2009-07-14 06:39 - 00158175 _____ () C:\Windows\setupact.log
2015-04-30 13:57 - 2010-07-16 00:50 - 01319098 _____ () C:\Windows\PFRO.log
2015-04-30 13:57 - 2010-05-27 08:51 - 01554676 _____ () C:\Windows\WindowsUpdate.log
2015-04-30 13:56 - 2015-02-08 18:13 - 00000000 ____D () C:\AdwCleaner
2015-04-30 13:46 - 2010-08-19 14:18 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-30 13:38 - 2013-12-17 14:22 - 00000364 _____ () C:\Windows\Tasks\WpsUpdateTask_Sylwia.job
2015-04-30 13:28 - 2015-02-10 13:23 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-30 13:27 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\Performance
2015-04-29 19:19 - 2011-09-26 20:19 - 00000000 ____D () C:\Qoobox
2015-04-29 19:15 - 2011-09-26 20:19 - 00000000 ____D () C:\Windows\ERDNT
2015-04-29 19:15 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2015-04-29 17:17 - 2015-02-07 17:02 - 05619691 ____R (Swearware) C:\Users\Sylwia\Desktop\ComboFix.exe
2015-04-29 16:35 - 2015-02-07 16:22 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-04-29 16:10 - 2015-02-10 13:53 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-04-28 12:33 - 2012-07-07 12:13 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-24 18:48 - 2009-07-14 06:53 - 00032618 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-16 16:31 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-15 23:51 - 2014-06-29 13:17 - 00000000 ____D () C:\Users\Sylwia\AppData\Roaming\uTorrent
2015-04-15 23:48 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-15 22:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-15 22:39 - 2015-01-19 03:03 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-15 22:39 - 2014-05-07 11:37 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-15 19:06 - 2013-12-06 21:04 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 18:50 - 2010-05-31 02:50 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 18:49 - 2010-05-27 08:53 - 00775124 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-15 18:45 - 2010-08-19 14:16 - 00000000 ____D () C:\ProgramData\Skype
2015-04-15 11:27 - 2015-02-10 13:23 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 11:27 - 2011-12-16 12:54 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-09 17:05 - 2010-08-19 14:18 - 00000000 ____D () C:\Users\Sylwia\AppData\Roaming\Skype
2015-03-31 00:13 - 2015-03-30 18:06 - 00000000 ____D () C:\Users\Sylwia\Desktop\Malarstwo użytkowanie mediów |